Executive brief
A vulnerability in the installation process of Bizerba _connect.BRAIN software incorrectly modifies system-wide folder permissions on Windows computers. Instead of securing its own data, the installer grants every user on the system full control over the shared ProgramData folder. This could allow a low-privileged user to access, modify, or delete sensitive data belonging to other applications or the operating system, potentially leading to a full system compromise.
Technical details
An incorrect default permissions vulnerability (CWE-276) exists in the LogPathConfig.exe component used during the setup of Bizerba _connect.BRAIN. During installation, the tool deletes existing ACLs on the global %ProgramData% directory and replaces them with a configuration that grants the 'Everyone' group full control. This is a significant deviation from the intended behavior of only restricting access to specific subdirectories like %ProgramData%\Bizerba\_connect.BRAIN. A local attacker with low privileges can exploit this to manipulate files belonging to other services or users, potentially leading to privilege escalation or data loss. The issue is resolved in version 5.06 by removing the execution of the faulty tool from the setup process.
Affected products
- Bizerba SE & Co. KG _connect.BRAIN versions prior to 5.06
Timeline
- 2026-07-20: advisory: NVD publication date
- 2026-07-20: disclosed: Bizerba security advisory published